Every cyberattack, whether a phishing email or a ransomware deployment, follows a specific structure. This structure includes an adversary, a capability, the infrastructure needed to carry out the attack, and a victim The Diamond Model of Intrusion Analysis can help understand what happened during an attack.
The Diamond Model shows how all the pieces of an attack fit together. It helps answer questions like who did it, how they did it, what tools they used, and who or what was affected. It is different from MITRE ATT&CK, which focuses on the attack tactics and techniques, or the Cyber Kill Chain which outlines the attack sequence. How? In short, the Diamond Model lets security teams connect the dots between the 4 elements of an attack
In this article, we break down the Diamond Model of Intrusion Analysis and explain why it is a key part of threat intelligence
Key takeaways
- The Diamond Model of Intrusion Analysis breaks a cyberattack into 4 connected parts: the adversary, the capability, the infrastructure, and the victim.
- The model helps with the analysis of what happened during an attack, who was responsible, how it was carried out, and what infrastructure was used.
- Unlike the Cyber Kill Chain or MITRE ATT&CK, the Diamond Model focuses on the relationships between the attack elements, which enables it to spot patterns across multiple incidents.
- Some analysts claim that the Diamond Model may oversimplify intrusion analysis in some cases.
- The model is a very useful threat intelligence tool for businesses to prioritize defenses, guide security spending, and speed up incident response.
What is the Diamond Model of Intrusion Analysis?
The Diamond Model of Intrusion Analysis helps security analysts understand cyberattacks. It breaks down an intrusion into 4 core components and shows how they relate to one another.
A cybersecurity researcher and author, Chris Sanders said that intrusion analysis is as much about tcpdump as astronomy is about telescopes In other words, an attack analysis shouldn’t be narrowed down to one element. Only by analyzing all 4 elements together can the complete picture of the attack be seen.
In a 2013 technical report for the US Department of Defense, Sergio Caltagirone, Andrew Pendergast, and Christopher Betz introduced the Diamond Model. They developed the model to make intrusion analysis easier and more complete. Since then, the model has been incorporated into cybersecurity courses and certification programs, such as CompTIA Security+, CySA+, and the EC-Council’s Certified Ethical Hacker (CEH).
How does the model work? It explains every cyber intrusion by looking at the 4 interconnected elements shown in a diamond-shaped diagram Security teams use the model to answer the following questions about every attack:
- Who is the adversary
- What capabilities such as tools, methods, and skills, did they use?
- What infrastructure supported the attack?
- Who or what was the victim

4 key elements of the Diamond Model of Intrusion Analysis
The adversary: who is behind the attack?
The adversary is the person or group responsible for the attack. When you start an analysis, you might not know exactly who they are. The Diamond Model helps you analyze the following:
- The threat actor’s identity, name, or pseudonym
- Entities sponsoring or endorsing the attackers
- Their geographical origin
- Their motivations, such as financial gain, espionage, disruption, or hacktivism
- Any indicators that link them to past attacks
The capability: what tools and techniques do attackers use?
This element gives you insights into the attackers’ skills, tools, malware, and level of sophistication It allows you to analyze how an adversary prepares for, carries out, and delivers an intrusion. Key capabilities may include:
- Reconnaissance techniques used to identify targets and weaknesses
- Methods used to deliver phishing emails, malware, or other payloads
- Skills for exploiting known or unknown vulnerabilities
- Malware and backdoor deployment (how skilled they are at carrying out remote-controlled attacks)
- Tool development and refinement abilities
Attackers often reuse these capabilities across multiple campaigns. The same malware, exploit, or phishing template can help analysts connect separate incidents to the same adversary.
The infrastructure: what systems does the attacker use to carry out the attack?
Infrastructure is the technical foundation that an adversary relies on to carry out an intrusion This covers:
- Command-and-control (C2) domains (what domain names are used)
- C2 server locations
- C2 server types
- C2 mechanisms and structure
- Compromised systems
- Paths of data leakage
Like capabilities, infrastructure is often reused across multiple attacks. Cybercriminals often stick to the same C2 domain for months or years, or rotate through a small set of compromised servers. When you identify the infrastructure they used in an attack, you can search for other incidents involving it—and those incidents often connect to the same adversary or campaign.
The victim: who or what is being targeted?
A victim is the target of an attack, whether it’s an organization, system, person, or data. Identifying the victim is useful because it shows:
- Which industries or sectors are currently at risk
- Whether attacks are highly targeted or launched at many targets
- The attacker’s actual motive (for example, a nation-state targeting government agencies looks different from a cybercriminal targeting banks)
- Potential future targets (patterns in victim selection suggest where attacks might strike next)
If analysts see the same type of organization being targeted across multiple incidents by different actors using different tools, it signals that the industry is facing an active threat.
How the 4 elements of the Diamond Model connect
The 4 elements of the model have different relationships with each other. Here are the ones that matter most in practice:
- Capability ↔ infrastructure Uncovers how tools are deployed and hosted, and how they communicate with the infrastructure.
- Adversary ↔ infrastructure Reveals the technical resources that the threat actor controls, acquires, or sets up.
- Adversary ↔ capability Shows how a cybercriminal owns, builds, or trains with attack tools and techniques.
- Infrastructure ↔ victim Shows which victims are reached through which infrastructure. For example, it shows whether victims are reached through phishing emails from a specific sender domain or exploit traffic from a specific IP range.
- Adversary ↔ victim This is about the attackers’ intent or motivation. Helps see who the target is and why.
- Capability ↔ victim Explains how specific tools affect specific targets.
This way of thinking becomes clear when you analyze an intrusion. If you have 3 of the 4 pieces, you can often identify the last one. Here is how it works in practice:
- Say you find a malicious domain (infrastructure) used in previous attacks. You identify a malware family or technique linked to those attacks (known capability), and see that the targets are all healthcare organizations (known victims). Now, you can narrow down which threat actors are likely to be responsible.
- In another case, you identify a specific backdoor (capability) communicating with a C2 server (infrastructure) previously linked to an organized cyber gang (known adversary). The affected systems are in the financial services industry (identifying the victim). This tells you that the gang is active in the financial services industry and is still using that backdoor.
Meta-features: the context behind each attack event
The Diamond Model goes deeper than just the 4 core elements. It also captures meta-features, which provide additional context about each attack:
- Timestamp Specifies exactly when the attack happened. Recognizing that a threat group always attacks during specific business hours or in specific time zones can help your team prepare.
- Phase Answers the question of which stage of the attack lifecycle the event represents. For example, is it reconnaissance, weaponization, or delivery, for example? It connects the Diamond Model to sequential frameworks like the Cyber Kill Chain.
- Result This is about the outcome of the intrusion. Did it succeed or fail? Or maybe it was only partially successful. Tracking successes vs. failures shows which techniques are the most effective.
- Direction Allows analysts to determine the path of the attack, such as whether it was adversary-to-victim or victim-to-adversary.
- Methodology Enables understanding of how the adversary executed the attack, whether by phishing, a watering hole attack, or a supply chain compromise.
- Resources. Focuses on the external assets that the attacker needed to execute the attack, such as financial funds, legal entities, and hardware.
These meta-features turn a single security alert into something analysts can use to compare dozens of incidents, revealing patterns in how specific threat actors operate.
Mapping an activity thread: the socio-political and technological axis
An activity thread connects several Diamond Model events across different stages of an attack By placing these events in order, analysts can see how an intrusion develops over time and how one event leads to the next.
The extended Diamond Model can add more context to that thread. For example, the socio-political axis can help analyze why the adversary is attacking, and the technology axis can show the tools, infrastructure, and techniques used during the attack.
- Start by defining the attacker’s socio-political goal For example, an organized cybercrime group may target aviation companies to steal intellectual property. This motive usually remains the same throughout the campaign.
- Next, arrange each event by timestamp and attack phase This shows how the operation progressed from the initial access stage to the later stages.
- Track changes in capabilities and infrastructure from phase to phase A phishing phase may use a malicious macro document, while a later phase may rely on an executable payload and different command-and-control servers.
- Connect separate events The same malware, IP address, domain, or attack method may indicate that several incidents belong to the same campaign.
Here is an example of how it works:

The Diamond Model of Intrusion Analysis vs. other cybersecurity frameworks
The Diamond Model does not replace other threat intelligence frameworks; rather, it complements them. Each framework examines cyberattacks from a different angle so security teams often use several together.
Framework | Focus | Key strength | Best use case |
|---|---|---|---|
The Diamond Model | Relationships between the adversary, capability, infrastructure, and victim | Connects known evidence and helps analysts see the big picture of an intrusion | Campaign mapping, threat actor profiling, and attribution |
The Cyber Kill Chain | The sequence of attack stages | Shows how an attack progresses and where defenders can interrupt it | Incident timeline reconstruction and security gap analysis |
MITRE ATT&CK | Specific attacker tactics, techniques, and procedures (TTP) | Provides detailed descriptions of attacker behavior and related detection methods | Detection engineering, threat-informed defense, and red team exercises |
The Diamond Model vs. the Cyber Kill Chain
The Cyber Kill Chain is a linear framework that describes an attack in 7 distinct stages:
- Reconnaissance
- Weaponization
- Delivery
- Exploitation
- Installation
- Command and control
- Actions on objectives
The Diamond Model works differently. It focuses on relationships rather than the sequence of events It helps you figure out who is linked to what and identifies which parts of an attack are related to other incidents.
Despite their differences, the Diamond Model and the Cyber Kill Chain can be used together for intrusion analysis. For example, a security team might use the Cyber Kill Chain to get the timeline of an incident right, then use the Diamond Model to link those specific details to other threats. If a phishing email appears during the delivery phase, for example, it might rely on the same setup used in a previous case. Spotting that overlap is exactly what the Diamond Model is for.
The Diamond Model vs. MITRE ATT&CK
MITRE ATT&CK describes the tactics, techniques, and procedures (TTP) that an attacker uses. It catalogs hundreds of specific techniques and maps them to threat actors.
For example, MITRE ATT&CK currently contains 222 techniques, 475 sub-techniques, and 172 tracked groups which makes it the most detailed framework.
The Diamond Model identifies the adversary, capability, infrastructure, and victim, but does not drill down into the specific technical details of each technique.
How do these two frameworks work together? First, a security team uses the Diamond Model to identify that a threat actor is active and which infrastructure they control. Then, they use MITRE ATT&CK to look up the specific techniques that the attacker has used, so they can improve detection and implement targeted defenses.
Using all 3 frameworks together
The best approach is to use all 3 frameworks together:
- The Cyber Kill Chain gives you the sequence of events in an attack timeline.
- The Diamond Model shows you the relationships between attack components, which helps connect related incidents and attribute attacks.
- MITRE ATT&CK provides the technical details needed for effective threat detection and response
Together, these frameworks give a complete picture of what happened (MITRE ATT&CK), the order of events (the Cyber Kill Chain), and who was connected to what (the Diamond Model).
Real-world examples
The Diamond Model has helped effectively analyze some of the most significant cyber intrusions.
SolarWinds supply chain attack (2020)
In this case, a Russian state-sponsored group called APT29 embedded malware into official SolarWinds Orion software updates. The model mapped out the event this way:
- The adversary APT29 (Russian SVR)
- The capability SUNBURST backdoor
- The infrastructure Compromised software supply chain and dedicated C2 domains
- The victim 200+ organizations, including US government agencies
The Diamond Model applied in the SolarWinds case study allowed experts to better understand a supply chain attack where one piece of malware reached hundreds of different targets.
LAPSUS$ data extortion group
The Diamond Model was also used to analyze LAPSUS$’s operations in 2022:
- The adversary LAPSUS$ (financially motivated hacking group)
- The capabilities Social engineering, DDoS attacks, credential theft, and data theft
- The infrastructure Open-source hacking tools, Telegram, underground forums
- The victims Companies in the telecommunications, software, technology, and gaming industries
By mapping these relationships, analysts could anticipate which industries might be hit next. It gave defenders a better chance to get ready.
Limitations of the Diamond Model
Although the Diamond Model is useful, some analysts argue it sometimes oversimplifies intrusion analysis Here are specific drawbacks to be aware of:
- Attribution is still hard. Even if you perform a deep analysis, it’s often tough to pin down exactly who is behind an attack. Sophisticated adversaries frequently use third-party operators, false flags, or shared infrastructure to mask their true identities.
- Complicated attacks don’t always fit into 4 neat categories. Cases like insider threats, supply-chain compromises, or campaigns involving multiple targets and attackers can blur the lines between adversary, capability, infrastructure, and victim.
- The 4 elements of the model are not sequential. Analysts use meta-features, such as timestamps and phases, to show how an attack progresses over time, and then connect related events through activity threads that place them in the phase order.
- Success depends on having high-quality data. You need solid information about the victims, capabilities, infrastructure, and adversaries to make this work. If an organization doesn’t have access to threat intelligence tools, building a model that actually helps will be hard.
- It can eat up a lot of an analyst’s time. A full Diamond Model analysis requires constant data gathering and relationship mapping. Teams without dedicated threat intel experts might find the constant shifting between known and unknown facts a bit overwhelming.
- The model’s predictive value depends on the intelligence available Activity threads and activity groups can help analysts identify likely future attack paths, targets, and adversary behavior, but these predictions depend on having enough reliable historical data to reveal useful patterns.
- There is a risk of focusing too much on attribution. Pinning a name on an attacker has its benefits, yet it can also pull a team’s attention away from more pressing goals. Sometimes, it’s better to focus on the incident itself.
How businesses use the Diamond Model in practice
Despite its limitations, the Diamond Model is widely used in real-world security operations:
Identifying threat actors that target your industry
By looking at which adversaries go after organizations in your sector, you can focus your defenses on the most likely threats. For example, if you know that a specific cyber gang is targeting financial services, you can allocate threat intelligence resources to tracking that group.
Linking related incidents across your organization
When a security team discovers malware in one part of the organization, they can use the Diamond Model to search for the same malware, infrastructure, or adversary patterns elsewhere. This often helps reveal breaches that might otherwise go undetected.
Making better security spending decisions
Knowing the tools and infrastructure your adversaries use helps you invest in the right defensive tools. If your industry is targeted by attacks using a particular exploit, patching that vulnerability should be a top priority. Likewise, if attackers are using specific command-and-control infrastructure, you can configure your firewall rules to block it.
Improving incident response
While an incident is happening, the Diamond Model helps responders ask the right questions. What infrastructure has the attacker used? What other systems might be compromised? Can we attribute this to a known threat actor? This structured approach speeds up the investigation and containment process.
Supporting threat intelligence operations
Security teams use the Diamond Model to document incidents, share threat information with peers, and collaborate across departments.
Conclusion
The Diamond Model is a valuable tool for intrusion analysis. Security teams can use this model to connect incidents, identify attacker patterns, and make more informed defense decisions. By examining the 4 key components of an attack (adversaries, capabilities, infrastructure, and victims), organizations can gain a better understanding of the threats they face
For a more comprehensive approach, you can combine the Diamond Model with MITRE ATT&CK and the Cyber Kill Chain. It’s also a good idea to integrate advanced threat intelligence into your security operations, as this can help you stay ahead of new attacks.
